Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2018-19873

An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data.

Fix: 5.11.3+
Fix from $2,300 2018-12-26
Debian Linux HIGH 8.8
CVE-2018-19870

An issue was discovered in Qt before 5.11.3. A malformed GIF image causes a NULL pointer dereference in QGifHandler resulting in a segmentation fault.

Fix: 5.11.3+
Fix from $1,950 2018-12-26
Debian Linux MEDIUM 5.3
CVE-2018-20217

A Reachable Assertion issue was discovered in the KDC in MIT Kerberos 5 (aka krb5) before 1.17. If an attacker can obtain a krbtgt ticket using an ol…

Fix: 5-1.17+
Fix from $1,600 2018-12-26
Debian Linux HIGH 8.8
CVE-2018-15518

QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML document.

Fix: 5.11.3+
Fix from $1,950 2018-12-26
Debian Linux MEDIUM 6.5
CVE-2018-20467

In coders/bmp.c in ImageMagick before 7.0.8-16, an input file can result in an infinite loop and hang, with high CPU and memory consumption. Remote a…

Fix: 6.9.10-16 / 7.0.8-16+
Fix from $1,600 2018-12-26
Debian Linux CRITICAL 9.8
CVE-2018-20433

c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.

Patch available
Fix from $2,300 2018-12-24
Debian Linux MEDIUM 6.5
CVE-2018-20430

GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the function history_extract() in plugins/ole2_extractor.c, related to EXTRAC…

Fix: after 1.8
Fix from $1,600 2018-12-24
Debian Linux MEDIUM 6.5
CVE-2018-20431

GNU Libextractor through 1.8 has a NULL Pointer Dereference vulnerability in the function process_metadata() in plugins/ole2_extractor.c.

Fix: after 1.8
Fix from $1,600 2018-12-24
Debian Linux MEDIUM 5.5
CVE-2018-20360

An invalid memory address dereference was discovered in the sbr_process_channel function of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (F…

Fix: 2.9.0+
Fix from $1,600 2018-12-22
Debian Linux HIGH 7.8
CVE-2018-19134

In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could e…

Fix: after 9.25
Fix from $1,950 2018-12-20
Debian Linux CRITICAL 9.8
CVE-2018-1160EPSS 87%

Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data.…

Fix: 1.2-7742-5 / 3.1.12+
Fix from $2,300 2018-12-20
Debian Linux HIGH 8.8
CVE-2018-1000877

libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in …

Fix: 3.4.0+
Fix from $1,950 2018-12-20
Debian Linux HIGH 8.8
CVE-2018-1000878

libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability …

Fix: 3.4.0+
Fix from $1,950 2018-12-20
Debian Linux HIGH 7.5
CVE-2018-20022

LibVNC before 2f5b2ad1c6c99b1ac6482c95844a84d66bb52838 contains multiple weaknesses CWE-665: Improper Initialization vulnerability in VNC client code…

Fix: 0.9.12+
Fix from $1,950 2018-12-19
Debian Linux HIGH 7.5
CVE-2018-20023

LibVNC before 8b06f835e259652b0ff026898014fc7297ade858 contains CWE-665: Improper Initialization vulnerability in VNC Repeater client code that allow…

Fix: 0.9.12+
Fix from $1,950 2018-12-19
Debian Linux HIGH 7.8
CVE-2018-20196

There is a stack-based buffer overflow in the third instance of the calculate_gain function in libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder…

No fix yet
Fix from $1,950 2018-12-18
Debian Linux MEDIUM 5.5
CVE-2018-20199

A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability…

Fix: 2.9.0+
Fix from $1,600 2018-12-18
Debian Linux MEDIUM 6.5
CVE-2018-20189

In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a crash and denial of service via a dib file that is…

Patch available
Fix from $1,600 2018-12-17
Debian Linux MEDIUM 6.5
CVE-2018-20184

In GraphicsMagick 1.4 snapshot-20181209 Q8, there is a heap-based buffer overflow in the WriteTGAImage function of tga.c, which allows attackers to c…

Patch available
Fix from $1,600 2018-12-17
Debian Linux MEDIUM 5.3
CVE-2018-20185

In GraphicsMagick 1.4 snapshot-20181209 Q8 on 32-bit platforms, there is a heap-based buffer over-read in the ReadBMPImage function of bmp.c, which a…

Patch available
Fix from $1,600 2018-12-17
Debian Linux MEDIUM 5.4
CVE-2018-18245

Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plu…

No fix yet
Fix from $1,600 2018-12-17
Debian Linux MEDIUM 5.3
CVE-2018-16872

A flaw was found in qemu Media Transfer Protocol (MTP). The code opening files in usb_mtp_get_object and usb_mtp_get_partial_object and directories i…

Fix: after 3.1.0
Fix from $1,600 2018-12-13
Debian Linux MEDIUM 6.5
CVE-2018-20097

There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote…

Patch available
Fix from $1,600 2018-12-12
Debian Linux MEDIUM 6.5
CVE-2018-19968

An attacker can exploit phpMyAdmin before 4.8.4 to leak the contents of a local file because of an error in the transformation feature. The attacker …

Fix: 4.8.4+
Fix from $1,600 2018-12-11
Debian Linux MEDIUM 6.1
CVE-2018-19970

In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafte…

Fix: 4.8.4+
Fix from $1,600 2018-12-11
Debian Linux HIGH 8.8
CVE-2018-20004

An issue has been found in Mini-XML (aka mxml) 2.12. It is a stack-based buffer overflow in mxml_write_node in mxml-file.c via vectors involving a do…

No fix yet
Fix from $1,950 2018-12-10
Debian Linux HIGH 8.8
CVE-2018-19966

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain host OS pr…

Fix: after 4.11.1
Fix from $1,950 2018-12-08
Debian Linux HIGH 7.8
CVE-2018-19961

An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes d…

Fix: after 4.11.1
Fix from $1,950 2018-12-08
Debian Linux HIGH 7.8
CVE-2018-19962

An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU m…

Fix: after 4.11.1
Fix from $1,950 2018-12-08
Debian Linux MEDIUM 6.5
CVE-2018-19967

An issue was discovered in Xen through 4.11.x on Intel x86 platforms allowing guest OS users to cause a denial of service (host OS hang) because Xen …

Fix: after 4.11.1
Fix from $1,600 2018-12-08